pub struct CredentialPolicy {
pub credentials: Vec<CredentialBinding>,
}Expand description
The complete credential section of a machine’s network policy.
Fields§
§credentials: Vec<CredentialBinding>Bindings the machine may use, in declaration order.
Implementations§
Source§impl CredentialPolicy
impl CredentialPolicy
Sourcepub fn validate(
&self,
network_allowed_hosts: Option<&[String]>,
) -> Result<(), PolicyError>
pub fn validate( &self, network_allowed_hosts: Option<&[String]>, ) -> Result<(), PolicyError>
Validate structure and, when the machine also restricts egress by
hostname, require every credential host to be reachable under that
allow-list. network_allowed_hosts = None means the machine’s network is
not hostname-restricted; the credential’s own list still applies.
Sourcepub fn bindings_for_host<'a>(
&'a self,
host: &'a str,
) -> impl Iterator<Item = &'a CredentialBinding> + 'a
pub fn bindings_for_host<'a>( &'a self, host: &'a str, ) -> impl Iterator<Item = &'a CredentialBinding> + 'a
Bindings permitted to substitute toward host, in declaration order.
Sourcepub fn binding(&self, name: &str) -> Option<&CredentialBinding>
pub fn binding(&self, name: &str) -> Option<&CredentialBinding>
Look up a binding by name.
Sourcepub fn guest_env<'a>(
&'a self,
placeholders: &'a BTreeMap<String, String>,
) -> impl Iterator<Item = (String, String)> + 'a
pub fn guest_env<'a>( &'a self, placeholders: &'a BTreeMap<String, String>, ) -> impl Iterator<Item = (String, String)> + 'a
Guest environment assignments (environment_variable, placeholder).
Bindings without a placeholder are skipped; callers persist placeholders
alongside the policy so this can never silently regenerate them.
Trait Implementations§
Source§impl Clone for CredentialPolicy
impl Clone for CredentialPolicy
Source§impl Debug for CredentialPolicy
impl Debug for CredentialPolicy
Source§impl Default for CredentialPolicy
impl Default for CredentialPolicy
Source§impl<'de> Deserialize<'de> for CredentialPolicywhere
CredentialPolicy: Default,
impl<'de> Deserialize<'de> for CredentialPolicywhere
CredentialPolicy: Default,
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Deserialize this value from the given Serde deserializer. Read more
impl Eq for CredentialPolicy
Source§impl PartialEq for CredentialPolicy
impl PartialEq for CredentialPolicy
Source§impl Serialize for CredentialPolicy
impl Serialize for CredentialPolicy
impl StructuralPartialEq for CredentialPolicy
Auto Trait Implementations§
impl Freeze for CredentialPolicy
impl RefUnwindSafe for CredentialPolicy
impl Send for CredentialPolicy
impl Sync for CredentialPolicy
impl Unpin for CredentialPolicy
impl UnsafeUnpin for CredentialPolicy
impl UnwindSafe for CredentialPolicy
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more